PoC Archive PoC Archive

tag

Lfi

Critical
ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)
CVE-2025-63888· ThinkPHP (top10.org / TopThink PHP framework) unpatched
Critical
Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294)
CVE-2025-2294· Kubio AI Page Builder (WordPress plugin) unpatched
Critical
Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236)
CVE-2025-54236· Adobe Commerce / Magento Open Source — customer/address_file/upload endpoint (dubbed "SessionReaper") patched
High
Termix Stored XSS via Malicious SVG Upload -> LFI / Session Hijack (CVE-2026-22804 / GHSA-m3cv-5hgp-hv35)
CVE-2026-22804 (GHSA-m3cv-5hgp-hv35)· Termix (Electron-based SSH/terminal manager), File Manager component (FileViewer.tsx) patched
High
Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)
CVE-2026-0926· Prodigy Commerce (WordPress plugin) unpatched
High
Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)
CVE-2026-45504· Microsoft Exchange Server (OWA / EWS) patched
Medium
Dolibarr selectobject.php Authenticated Local File Inclusion (CVE-2026-34036)
CVE-2026-34036· Dolibarr ERP/CRM unpatched
Critical
Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11)· Discuz! X5.0 (PHP-based forum/CMS software) unpatched
Critical
BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515
CVE-2026-7515· BetterDocs Pro (WordPress plugin) unpatched